CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

FBI raises alarm over deceptive phishing campaign targeting prominent people

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5508

As cited

Copy frozen at (site build).

threat intel

FBI raises alarm over deceptive phishing campaign targeting prominent people

The FBI has issued a warning about a sophisticated phishing campaign that has been active since late 2025, targeting high-profile individuals and their associates through commercial messaging applications. Attackers use social engineering to trick victims into granting OAuth consent to malicious applications impersonating legitimate cloud services like Microsoft and Google, giving the threat actors persistent access to email, files, and other sensitive data that cannot be revoked by changing passwords. The attackers have impersonated government officials, journalists, and public figures, and bypass both passwords and multifactor authentication (MFA) through this consent phishing technique.

Why it matters: High-profile individuals, their family members, and business associates face account compromise and data theft; all practitioners should educate users that approving OAuth requests from unfamiliar senders grants persistent access that MFA does not block and can only be revoked through security settings.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

FBI raises alarm over deceptive phishing campaign targeting prominent people

The FBI has issued a warning about a sophisticated phishing campaign that has been active since late 2025, targeting high-profile individuals and their associates through commercial messaging applications. Attackers use social engineering to trick victims into granting OAuth consent to malicious applications impersonating legitimate cloud services like Microsoft and Google, giving the threat actors persistent access to email, files, and other sensitive data that cannot be revoked by changing passwords. The attackers have impersonated government officials, journalists, and public figures, and bypass both passwords and multifactor authentication (MFA) through this consent phishing technique.

Why it matters: High-profile individuals, their family members, and business associates face account compromise and data theft; all practitioners should educate users that approving OAuth requests from unfamiliar senders grants persistent access that MFA does not block and can only be revoked through security settings.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary